Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | February 2006 (4.02) |
| Protection available since | 14 December 2005 22:25:37 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Rbot-BCC is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-BCC runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
The worm attempts to spread by copying itself to remote network shares with weak passwords and by exploiting the following system vulnerabilities: LSASS (MS04-011), RPC-DCOM (MS04-012), WebDav (MS03-007) and UPNP (MS01-059). W32/Rbot-BCC is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-BCC runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
The worm attempts to spread by copying itself to remote network shares with weak passwords and by exploiting the following system vulnerabilities: LSASS (MS04-011), RPC-DCOM (MS04-012), WebDav (MS03-007) and UPNP (MS01-059).
When first run W32/Rbot-BCC copies itself to <System>\logonnui.exe.
The following registry entries are created to run logonnui.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Logon User Interface
logonnui.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Logon User Interface
logonnui.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Logon User Interface
logonnui.exe
Registry entries are set as follows:
HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1
